Intel

AIKIDO-2025-10074

dompurify is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-26791

45

Medium Risk

This Affects:

JAVAdompurify
1.0.0 - 3.2.3
Fixed in 3.2.4

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) due to a flaw in the DOMPurify.sanitize function. This vulnerability allows attackers to bypass the sanitization process, potentially injecting and executing malicious scripts even when the function is used as intended.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

dompurify is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 3.2.3.

How to fix this

Upgrade the org.webjars.bowergithub.cure53:dompurify library to a patch version.